← Blog

Grubhub Confirms 2026 Data Theft Amid ShinyHunters Extortion Reporting

Share on X

In January 2026, Grubhub confirmed that unauthorized individuals had downloaded data from certain company systems, while stating categories such as financial information and order history were not affected. Coverage described engagement with forensics and law enforcement and noted extortion narratives involving the group ShinyHunters, including alleged pressure tied to both older Salesforce-era claims and newer Zendesk support data—often discussed alongside the Salesloft Drift OAuth/token theft wave.

Canonical record: Grubhub 2026 on BreachHistory (distinct from prior Grubhub breach years in the database).

Sources: BleepingComputer